Behavior-Centric Malware Classification with Fine-Grained Malicious Logic Localization

📅 2026-09-29
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the inability of existing black-box malware detectors to provide fine-grained localization of malicious logic origins and specific behaviors. To this end, we propose a behavior-centric analysis framework that constructs structured behavior graphs through context-sensitive backward API slicing and call chain reconstruction. The method integrates Transformers to capture instruction semantics with Graph Neural Networks (GNNs) to model structural dependencies, leveraging attention-based attribution mechanisms to achieve interpretable, precise classification and localization. Experimental results demonstrate that the proposed framework achieves superior performance across standard evaluation metrics and behavioral coverage. By overcoming the inherent limitations of traditional black-box approaches, this work enables high-accuracy malware classification alongside fine-grained localization of malicious logic.
📝 Abstract
Effective malware analysis requires understanding not only whether a program is malicious, but also which behaviors it exhibits and where those behaviors originate in the code. Existing machine-learning-based malware detectors largely operate as black boxes, providing limited insight into the malicious logic responsible for their decisions. This paper addresses malicious behavior localization and classification at the basic-block level. We propose a behavior-centric analysis framework that decomposes malware samples into behaviors and systematically links these behaviors to their originating code regions. Using context-sensitive backward slicing from security-relevant system API calls, we reconstruct control- and data-dependency chains and represent each behavior as a structured graph of related basic blocks. A Transformer-based model captures instruction-level semantics, while a Graph Neural Network models structural dependencies within behavior graphs. The resulting representations are fused to enable accurate and interpretable classification, with attention-based attribution identifying code regions responsible for malicious behaviors. We evaluate our approach using standard classification metrics and a behavior coverage metric that measures the detection of manually labeled malicious behaviors. Our results demonstrate that the proposed framework achieves accurate malware classification while providing fine-grained, behavior-aware localization of malicious logic.
Problem

Research questions and friction points this paper is trying to address.

Malware Classification
Malicious Behavior Localization
Black-box Detectors
Fine-grained Analysis
Innovation

Methods, ideas, or system contributions that make the work stand out.

Behavior-Centric Malware Classification
Fine-Grained Malicious Logic Localization
Context-Sensitive Backward Slicing
Graph Neural Network
Attention-Based Attribution
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
P
Prakriti Baral
Gianforte School of Computing, Montana State University, Bozeman, MT 59717, USA
Z
Zhuoyun Qian
College of Computer Science and Technology, Shandong University, Qingdao, Shandong 266237, China
H
Hailu Xu
Department of Computer Engineering and Computer Science, California State University, Long Beach, Long Beach, CA 90840, USA
Fangtian Zhong
Fangtian Zhong
Assistant Prof. @ Montana State University
Software SecuritySystem Security